The HITECH Act: What RHIA Candidates Must Know

Overview of the HITECH Act

The Health Information Technology for Economic and Clinical Health (HITECH) Act was enacted in 2009 as part of the American Recovery and Reinvestment Act. It strengthened HIPAA privacy and security enforcement while providing financial incentives for the meaningful use of certified electronic health record technology. RHIA candidates must know both the enforcement changes and the EHR incentive structure HITECH created.

Expanded HIPAA Enforcement

  • Introduced tiered civil monetary penalties based on the level of culpability, from unknowing violations to willful neglect
  • Extended HIPAA privacy and security obligations directly to business associates, not just covered entities
  • Established the Breach Notification Rule, requiring notification to affected individuals, HHS, and in some cases the media, following a breach of unsecured protected health information
  • Authorized state attorneys general to bring civil actions on behalf of state residents for HIPAA violations

The Breach Notification Rule

Under HITECH, a breach is presumed reportable unless the covered entity demonstrates a low probability that protected health information was compromised, based on a documented risk assessment considering the nature of the data involved, the unauthorized person who accessed it, whether the information was actually viewed, and the extent to which risk has been mitigated. Breaches affecting 500 or more individuals require notification to HHS without unreasonable delay and no later than 60 days, along with prominent media notice.

Meaningful Use and EHR Incentives

HITECH established the Medicare and Medicaid EHR Incentive Programs, later renamed the Promoting Interoperability Programs, which paid eligible providers and hospitals for demonstrating meaningful use of certified EHR technology across defined stages emphasizing data capture, clinical decision support, and patient engagement. Providers who failed to demonstrate meaningful use eventually faced downward payment adjustments under Medicare.

Business Associate Accountability

Before HITECH, business associates were bound only by contract; after HITECH, they became directly liable for HIPAA compliance and subject to the same civil and criminal penalties as covered entities. This change significantly increased the importance of business associate agreements and vendor risk management within HIM compliance programs.

Exam Tips

Expect questions on the four-factor breach risk assessment and on penalty tier classifications. Also expect questions distinguishing HITECH's business associate liability expansion from the original HIPAA framework, since this is a commonly tested contrast.

Key takeaway: HITECH transformed HIPAA enforcement and accelerated EHR adoption, and its breach notification and business associate provisions remain heavily tested Compliance domain content.

Ready to Start Studying?

Access 500+ flashcards, 30 mini exams, and 7 full-length practice exams.

Get Started Free

RHIApractice is not affiliated with or endorsed by AHIMA or Pearson VUE.